THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g29h-pfmp-qp9r (high) — CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

[GHSA] GHSA-g29h-pfmp-qp9r (high) — CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

highgithub_advisoriesPublished 2026-09-04

GHSA-g29h-pfmp-qp9r Severity: high CVE: CVE-2026-75857

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

### Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g29h-pfmp-qp9r